Large Images Uploader Security & Risk Analysis

wordpress.org/plugins/large-images-uploader

Upload large images to your wordpress without max size threshold and without failing because of your hosting timeout limits.

100 active installs v1.0.2 PHP 7.0+ WP 5.6+ Updated Aug 22, 2023
imageslargethresholdtimeoutupload
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Large Images Uploader Safe to Use in 2026?

Generally Safe

Score 85/100

Large Images Uploader has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'large-images-uploader' plugin v1.0.2 presents a very strong security posture. The plugin demonstrates excellent adherence to WordPress security best practices, with no identified vulnerabilities in its history. The static analysis reveals a minimal attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack proper authentication or permission checks. Furthermore, the code actively utilizes prepared statements for its SQL queries and shows a high rate of proper output escaping, minimizing the risk of common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. The presence of nonce checks, although limited, is a positive indicator of security awareness in the development. The use of the Select2 library is noted, but without information on its version or specific usage, it's difficult to assess any associated risks. The overall lack of critical or high-severity taint analysis findings and historical CVEs strongly suggests a well-developed and secure plugin.

Key Concerns

  • Limited capability checks found
  • Some output escaping is not proper
Vulnerabilities
None known

Large Images Uploader Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Large Images Uploader Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
6
26 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared4 total queries

Output Escaping

81% escaped32 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<Uploader> (includes\Uploader.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Large Images Uploader Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuincludes\Uploader.php:59
actionadmin_enqueue_scriptsincludes\Uploader.php:60
filterwp_prepare_attachment_for_jsincludes\Uploader.php:63
filterwp_image_editorsincludes\Uploader.php:64
filterwp_get_missing_image_subsizesincludes\WP_Large_Images_Uploader.php:90
filterintermediate_image_sizes_advancedincludes\WP_Large_Images_Uploader.php:91
filterbig_image_size_thresholdincludes\WP_Large_Images_Uploader.php:92
actionplugins_loadedlarge-images-uploader.php:179
Maintenance & Trust

Large Images Uploader Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedAug 22, 2023
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Large Images Uploader Developer Profile

GrandPlugins

20 plugins · 9K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
160 days
View full developer profile
Detection Fingerprints

How We Detect Large Images Uploader

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/large-images-uploader/assets/css/uploader.css/wp-content/plugins/large-images-uploader/assets/js/uploader.js/wp-content/plugins/large-images-uploader/assets/js/plugins/vue.min.js/wp-content/plugins/large-images-uploader/assets/js/plugins/vue-progressbar.min.js/wp-content/plugins/large-images-uploader/assets/js/plugins/vue-multiselect.min.js/wp-content/plugins/large-images-uploader/assets/js/plugins/axios.min.js/wp-content/plugins/large-images-uploader/assets/js/plugins/moment.min.js/wp-content/plugins/large-images-uploader/assets/js/plugins/moment-timezone-with-data.min.js+2 more
Script Paths
/wp-content/plugins/large-images-uploader/assets/js/uploader.js/wp-content/plugins/large-images-uploader/assets/js/plugins/vue.min.js/wp-content/plugins/large-images-uploader/assets/js/plugins/vue-progressbar.min.js/wp-content/plugins/large-images-uploader/assets/js/plugins/vue-multiselect.min.js/wp-content/plugins/large-images-uploader/assets/js/plugins/axios.min.js/wp-content/plugins/large-images-uploader/assets/js/plugins/moment.min.js+3 more
Version Parameters
large-images-uploader/assets/css/uploader.css?ver=large-images-uploader/assets/js/uploader.js?ver=large-images-uploader/assets/js/plugins/vue.min.js?ver=large-images-uploader/assets/js/plugins/vue-progressbar.min.js?ver=large-images-uploader/assets/js/plugins/vue-multiselect.min.js?ver=large-images-uploader/assets/js/plugins/axios.min.js?ver=large-images-uploader/assets/js/plugins/moment.min.js?ver=large-images-uploader/assets/js/plugins/moment-timezone-with-data.min.js?ver=large-images-uploader/assets/js/vue-app.js?ver=large-images-uploader/core/wp-image-editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
gpls-lidfw-large-images-uploader
HTML Comments
<!-- GrandPlugins --><!-- GPLS CORE GRANDPLUGINS --><!-- GPLS LIDFW -->
Data Attributes
data-gpls-plugins-general-prefixdata-classes-prefix
JS Globals
window.gpls_lidfw_large_images_uploader_localize_data
FAQ

Frequently Asked Questions about Large Images Uploader